Cruciferra Malware Loader Uses ClickFix Lures to Kill EDR
ID: 87c1bb46-9350-5b45-84a8-11ed4243a55f
STIX ID: report--87c1bb46-9350-5b45-84a8-11ed4243a55f
Feed Name: securityonline.info
Threat Score
Cruciferra’s malware loader (selling Remus stealer) is being delivered in late-July 2026 ClickFix campaigns via ErrTraffic-injected JavaScript on compromised WordPress sites; attackers use clipboard PowerShell lures to sideload a DLL, perform process hollowing into signed binaries, and optionally deploy a signed-but-vulnerable driver (DCRCVDrv.sys) to kill ~145 AV/EDR processes from kernel space, while C2 domains are resolved via blockchain smart contracts (EtherHiding).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
